The Data (Use and Access) Act 2025 amends UK GDPR on data subject rights and controller obligations
Original title: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 effect on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)
The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduces consequential amendments to the UK GDPR with transitional provisions effective from 23 June 2026. These amendments align UK data protection law with the new Data (Use and Access) Act 2025 framework. Organizations subject to UK GDPR must review updates to their data subject rights procedures, consent mechanisms, and controller obligations to ensure compliance with the amended requirements.
What changed
- The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 introduces changes to UK GDPR effective 23 June 2026 to align with the new Data (Use and Access) Act 2025
- Consequential amendments affect how data controllers must handle data subject rights requests and exercise their responsibilities under UK GDPR
- Transitional provisions establish a period for organizations to adapt their data processing practices and systems to comply with amended requirements
Who is affected
All organizations in the UK and those processing personal data of UK residents subject to UK GDPR, including data controllers and processors operating within the UK or serving UK data subjects
Summary generated by a language model; the official text prevails. Not legal advice.